SYMBOLCOMMON_NAMEaka. SYNONYMS
win.castle_stealer (Back to overview)

CASTLESTEALER


According to Elastic Security Labs, CASTLESTEALER is a .NET-based information-stealing malware family that is delivered in-memory by the OXLOADER loader using DonutLoader-generated shellcode. It is embedded as an encrypted and compressed .NET assembly that is decrypted, decompressed, and reflectively executed in memory to minimize on-disk artifacts. The family uses AES-encrypted communications with its command-and-control infrastructure, with a characteristic hard-coded key that has been reused across samples. As an infostealer targeting Windows environments, it is designed to collect sensitive data (such as user credentials and other information) and interacts with the system in memory to support discovery and data exfiltration while evading conventional detection.

References
2026-06-19ElasticDaniel Stepanic
Lost in relocation: analysis of a new loader distributing CASTLESTEALER
CASTLESTEALER

There is no Yara-Signature yet.